Wednesdays discovery of three mis issued TLS certificates for Cloudflares 1.1.1.1 encrypted DNS lookup service generated intense interest and concern among Internet security practitioners. The revelation raised the possibility that an unknown entity had obtained the cryptographic equivalent of a skeleton key that could be used to surreptitiously decrypt millions of users DNS queries that were encrypted through DNS over TLS or DNS over HTTPS. From there, the scammers could have read queries or...
